quiklkp.blogg.se

Bobafetts trainer v6.8 .dat file
Bobafetts trainer v6.8 .dat file









Worth to mention - Avast doesn't find anything suspicious in "C:\Program Files\Cheat Engine 6.3" directory. Basically, it contains some files from "C:\Program Files\Cheat Engine 6.3". As mentioned earlier in my posts, this is zlib archive, and contains essential files: two DLL files, one EXE file (cheatengine main EXE), one LUA file, one CETRAINER file (which is XOR-crypted CheatTable file). I removed RCData (Embedded data) with Resource Editor.Įxtracted from EXE resource, RCData, with Resource Editor:ĪRCHIVE - flagged as safe. His trainer is flagged as Win32:Malware-gen.īanished Trainer (x32).exe - flagged as Win32:Malware-genīanished Trainer (x32) (NO RCData).exe - flagged as safe, Avast doesn't find anything suspicious. Sadly, problem returns again.Īs an example, trainer made by CheatEngine forum member. It is an empty trainer generated with CE6.3, this EXE is standalonephase1.dat file with appended RCData emptyTrainer.EXE - (false positive - Win32:Evo-gen ). standalonephase1.dat (no virus detected)

bobafetts trainer v6.8 .dat file

Now standalonephase1.dat (from CE6.2 and CE6.3) file with appended RCData (ARCHIVE and DECOMPRESSOR, and changed icon) is treated as Win32:Evo-gen We can manually scan CheatEngine v6.2 installed inside "program files" folder - no threats detected. And downloaded (from trusted site) trainers do not work until I move them to excluded folder. I have to save my trainers to folder added to exclusion list. Standalone single player trainers are again blocked by Avast: Win32:Evo-gen And first post contains useful informations. I know this topic is old, but there's no other threads like this one. I even tried to compile DECOMPRESSOR myself with current Lazarus version 1.0.8. And CheatEngine is an "open source GPL" application. Well, I made that trainer and I know what it is exactly doing. You could say: "you downloaded trainer from untrusted site". lua and exe file (with the same name: gameName_trainer.exe)īut, AVAST treats DECOMPRESSOR as malware. For example as gameName_trainer.exeġ) When user launch gameName_trainer.exe, embedded data:ARCHIVE and DECOMPRESSOR, are saved inside temp dir (F:\temp\cetrainers\CET28.tmp\),ĭECOMPRESSOR as gameName_trainer.exe (yes, the same name)Ģ) then DECOMPRESSOR (gameName_trainer.exe) decompresses CET_Archive.dat into "extracted" folderģ) inside "extracted" there are.

bobafetts trainer v6.8 .dat file bobafetts trainer v6.8 .dat file

So, standalonephase1.dat file with changed icon, name and with embedded ARCHIVE and DECOMPRESSOR is final product. ARCHIVE and DECOMPRESSOR are embedded into final EXE (standalonephase1.dat file) and there is DECOMPRESSOR file (standalonephase2.dat file inside installed cheatengine dir) - this file, when launched, will decompress ARCHIVE and execute final EXE exe, are compressed with zlib into ARCHIVE Avast just ignore my exclude list.Ĭurrently, all CE6.2 trainers are made like this:

bobafetts trainer v6.8 .dat file

I'm using trainer created by CheatEngine6.2 and Avast shows message about virus:īut still, I can not launch trainer.











Bobafetts trainer v6.8 .dat file